MalwareConfig
Details
<table class="table table-striped table-bordered table-sm">
<tr>
<th>FileName</th>
<td><a href="/stats//">7cbc746a357d0236e5150232aa9c1a4ff02217fd4fee80cf72d1b134ebed3637.exe</a></td>
</tr>
<tr>
<th>Malware Family</th>
<td><a href="/stats//">NanoCore</a></td>
</tr>
<tr>
<th>Date Added</th>
<td>2022-01-02 22:53:41.042000</td>
</tr>
<tr>
<th>MD5</th>
<td>5c25422db7fe9fd4747213abdacdc193</td>
</tr>
<tr>
<th>Sha256</th>
<td>7cbc746a357d0236e5150232aa9c1a4ff02217fd4fee80cf72d1b134ebed3637</td>
</tr>
<tr>
<th>Robot</th>
<td>Robots lovingly delivered by <a href="https://robohash.org">robohash.org</a></td>
</tr>
</table>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="row mt-5">
<div class="col">
<div class="card">
<div class="card-header">
Advertising
</div>
<div class="card-body">
<!-- ducktoolkit-leaderboard -->
<ins class="adsbygoogle"
style="display:inline-block;width:728px;height:90px"
data-ad-client="ca-pub-1435553701793282"
data-ad-slot="1601555780"></ins>
</div>
</div>
</div>
</div>
<div class="row mt-5">
<div class="col">
<div class="card">
<div class="card-header">
Config Data
</div>
<table class="table table-striped table-bordered table-sm">
<tr>
<th>Version</th>
<td>b'\x071.2.2.0'</td>
</tr>
<tr>
<th>Mutex</th>
<td>b'\xbd\xb8u\xb5\x8c\xf8eA\xa4\x16\xd4\xb1\x16\xf4\xbau'</td>
</tr>
<tr>
<th>Group</th>
<td>b'Default'</td>
</tr>
<tr>
<th>Domain1</th>
<td>b'mback53388.duckdns.org'</td>
</tr>
<tr>
<th>Domain2</th>
<td>b'mback53388.duckdns.org'</td>
</tr>
<tr>
<th>Port</th>
<td>8909</td>
</tr>
<tr>
<th>RunOnStartup</th>
<td>b'\x01'</td>
</tr>
<tr>
<th>RequestElevation</th>
<td>b'\x00'</td>
</tr>
<tr>
<th>BypassUAC</th>
<td>b'\x01'</td>
</tr>
<tr>
<th>ClearZoneIdentifier</th>
<td>b'\x01'</td>
</tr>
<tr>
<th>ClearAccessControl</th>
<td>b'\x00'</td>
</tr>
<tr>
<th>SetCriticalProcess</th>
<td>b'\x00'</td>
</tr>
<tr>
<th>PreventSystemSleep</th>
<td>b'\x01'</td>
</tr>
<tr>
<th>EnableDebugMode</th>
<td>b'\x00'</td>
</tr>
<tr>
<th>ConnectDelay</th>
<td>4000</td>
</tr>
<tr>
<th>RestartDelay</th>
<td>5000</td>
</tr>
<tr>
<th>UseCustomDNS</th>
<td>b'\x01'</td>
</tr>
<tr>
<th>PrimaryDNSServer</th>
<td>b'8.8.8.8'</td>
</tr>
</table>
</div>
</div>
</div>
<div class="row mt-5">
<div class="col">
<div class="card">
<div class="card-header">
Virustotal
</div>
<div class="card-body">
<p>61 out of 68 AV Engines identified the sample as Malicious.</p>
<p><a href="https://www.virustotal.com/gui/file/7cbc746a357d0236e5150232aa9c1a4ff02217fd4fee80cf72d1b134ebed3637/detection/f-7cbc746a357d0236e5150232aa9c1a4ff02217fd4fee80cf72d1b134ebed3637-1641111450">Virustotal Report</a></p>
</div>
</div>
</div>
</div>